Home/Product/xstream
Product

xstream

37 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2022-41966
< 1.4.20
XStream serializes Java objects to XML and back again. Versions prior to 1.4.20 may allow a remote attacker to terminate the appli
8.2HIGH
CVE-2022-40152
< 1.4.20
Those using Woodstox to parse XML data may be vulnerable to Denial of Service attacks (DOS) if DTD support is enabled. If the pars
6.5MEDIUM
CVE-2022-40151
< 1.4.20
Those using Xstream to seralize XML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user su
6.5MEDIUM
CVE-2021-43859
< 1.4.19
XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a remote att
7.5HIGH
CVE-2021-39152
< 1.4.18
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote
8.5HIGH
CVE-2021-39150
< 1.4.18
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote
8.5HIGH
CVE-2021-39140
< 1.4.18
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote
6.5MEDIUM
CVE-2021-39154
< 1.4.18
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote
8.5HIGH
CVE-2021-39153
< 1.4.18
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote
8.5HIGH
CVE-2021-39151
< 1.4.18
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote
8.5HIGH
CVE-2021-39149
< 1.4.18
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote
8.5HIGH
CVE-2021-39148
< 1.4.18
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote
8.5HIGH
CVE-2021-39147
< 1.4.18
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote
8.5HIGH
CVE-2021-39146
< 1.4.18
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote
8.5HIGH
CVE-2021-39145
< 1.4.18
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote
8.5HIGH
CVE-2021-39144
< 1.4.18
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote
8.5HIGH
CVE-2021-39141
< 1.4.18
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote
8.5HIGH
CVE-2021-39139
< 1.4.18
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote
8.5HIGH
CVE-2021-29505
< 1.4.17
XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4.17 may al
7.5HIGH
CVE-2021-21351
< 1.4.16
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability m
5.4MEDIUM
CVE-2021-21350
< 1.4.16
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability w
5.3MEDIUM
CVE-2021-21349
< 1.4.16
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability w
6.1MEDIUM
CVE-2021-21348
< 1.4.16
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability w
5.3MEDIUM
CVE-2021-21347
< 1.4.16
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability w
6.1MEDIUM
CVE-2021-21346
< 1.4.16
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability w
6.1MEDIUM
CVE-2021-21345
< 1.4.16
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability w
5.8MEDIUM
CVE-2021-21344
< 1.4.16
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability w
5.3MEDIUM
CVE-2021-21343
< 1.4.16
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability w
5.3MEDIUM
CVE-2021-21342
< 1.4.16
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability w
5.3MEDIUM
CVE-2021-21341
< 1.4.16
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is vulnerability whi
7.5HIGH
CVE-2020-26259
< 1.4.15
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.15, is vulnerable to an Arbitr
6.8MEDIUM
CVE-2020-26258
< 1.4.15
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.15, a Server-Side Forgery Requ
6.3MEDIUM
CVE-2020-26217
< 1.4.14
XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrar
8.0HIGH
CVE-2019-10173
all versions
It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw. If the sec
9.8CRITICAL
CVE-2013-7285
<= 1.4.6
Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attack
9.8CRITICAL
CVE-2017-7957
<= 1.4.9
XStream through 1.4.9, when a certain denyTypes workaround is not used, mishandles attempts to create an instance of the primitive
7.5HIGH
CVE-2016-3674
< 1.4.9
Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDriver, (4) JDom2Driver, (5) Sjs
7.5HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin